๐ง๐ช
madeit
2026-09-10 16:20:20
(3 days ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:31:14
(1 month ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 21:59:33
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-04 06:23:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:23:14.390208 2026] [security2:error] [pid 13185:tid 13185] [client 172.70.115.199:9937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.teenybikini.com"] [uri "/.env.production"] [unique_id "adCuUjf4RufGiY89Z2kNCgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 20:13:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 16:13:39.800504 2026] [security2:error] [pid 1271:tid 1271] [client 172.70.115.199:11797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bostonscience.com"] [uri "/.env.docker"] [unique_id "acmH87VFohXOJXPhfExc8QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:03:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:03:14.566203 2026] [security2:error] [pid 16319:tid 16319] [client 172.70.115.199:11499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.trhs70.com"] [uri "/.env.orig"] [unique_id "abz_Qkbr9q1SNH1UqHaaGQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:54:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:53:56.564129 2026] [security2:error] [pid 12695:tid 12695] [client 172.70.115.199:14313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mindchill.net"] [uri "/config/.env"] [unique_id "abzS5P_wUHlLTCHHZaI2cAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:37:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:37:50.664119 2026] [security2:error] [pid 24373:tid 24373] [client 172.70.115.199:10697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.terazon.net"] [uri "/core/.env"] [unique_id "abzPHqZgM6P-u7fZ3GM4BwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:54:36
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:54:27.707444 2026] [security2:error] [pid 16369:tid 16369] [client 172.70.115.199:13741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brunerdevelopment.littlehorndesign.com"] [uri "/app/.env"] [unique_id "abzE86JVL05W0K0sYx9d3gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:55:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:55:05.775806 2026] [security2:error] [pid 11178:tid 11178] [client 172.70.115.199:9569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.genevainvestors.com"] [uri "/.env.dev"] [unique_id "aby3CWnX2yJPq-xbi_nGKgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:18:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.115.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:18:39.148192 2026] [security2:error] [pid 26679:tid 26679] [client 172.70.115.199:10191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mccompu.com"] [uri "/admin/.env"] [unique_id "abyufwGqgo60K4BhqPaP1wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-06 21:32:13
(1 year ago)
[Sat Sep 06 23:32:13.091955 2025] [authz_core:error] [pid 29890] [client 172.70.115.199:23190] AH016 ...
show more
[Sat Sep 06 23:32:13.091955 2025] [authz_core:error] [pid 29890] [client 172.70.115.199:23190] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Sep 06 23:32:13.209373 2025] [authz_core:error] [pid 29890] [client 172.70.115.199:23190] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Sep 06 23:32:13.332409 2025] [authz_core:error] [pid 29890] [client 172.70.115.199:23190] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2025-08-29 18:34:28
(1 year ago)
WordPress XMLRPC scan :: 172.70.115.199 - - [29/Aug/2025:18:34:26 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 172.70.115.199 - - [29/Aug/2025:18:34:26 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "http://[censored_1]/xmlrpc.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0"
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
HJ5Ss4Ju
2025-08-25 01:01:28
(1 year ago)
WordPress XMLRPC scan :: 172.70.115.199 - - [25/Aug/2025:01:01:27 0000] "GET /xmlrpc.php HTTP/1.1" ...
show more
WordPress XMLRPC scan :: 172.70.115.199 - - [25/Aug/2025:01:01:27 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "https://[censored_1]" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2025-07-18 07:23:12
(1 year ago)
2025-07-18 00:04:13,130 fail2ban.actions [841]: NOTICE [nginx-bad-request] Ban 172.70.115.19 ...
show more
2025-07-18 00:04:13,130 fail2ban.actions [841]: NOTICE [nginx-bad-request] Ban 172.70.115.199
2025-07-18 09:23:11,970 fail2ban.actions [841]: NOTICE [nginx-bad-request] Ban 172.70.115.199
...
show less
Port Scan
Brute-Force
Bad Web Bot